IBM Director Multiple Remote Input Validation Vulnerabilities
BID:19915
CVE-2006-4682 | CVE-2006-4683 |Info
IBM Director Multiple Remote Input Validation Vulnerabilities
| Bugtraq ID: | 19915 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4682 CVE-2006-4683 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2006 12:00AM |
| Updated: | Feb 20 2007 09:26PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
IBM Director 3.1 IBM Director 0 |
| Not Vulnerable: |
IBM Director 5.10 |
Discussion
IBM Director Multiple Remote Input Validation Vulnerabilities
IBM Director is prone to multiple input-validation vulnerabilities.
An attacker can exploit these issues to cause denial-of-service conditions, effectively denying service to legitimate users, and to access cookie and authentication data that may aid in further attacks.
IBM Director is prone to multiple input-validation vulnerabilities.
An attacker can exploit these issues to cause denial-of-service conditions, effectively denying service to legitimate users, and to access cookie and authentication data that may aid in further attacks.
Exploit / POC
IBM Director Multiple Remote Input Validation Vulnerabilities
An attacker can use standard network tools to exploit these issues.
An attacker can use standard network tools to exploit these issues.
Solution / Fix
IBM Director Multiple Remote Input Validation Vulnerabilities
Solution:
The vendor has released version 5.10 to address these issues.
Please see the referenced advisories for more information.
Solution:
The vendor has released version 5.10 to address these issues.
Please see the referenced advisories for more information.
References
IBM Director Multiple Remote Input Validation Vulnerabilities
References:
References:
- IBM Director Homepage (IBM)
- IBM Director Release Notes 5.10 (IBM)